Just a thought:
Does the secondary mailserver do the same kind of virus/spam checking as the primary server?
The reason I’m asking is because a lot of spam software deliberately target secondary/backup mailservers instead of the primary one.
Depending on how the forwarding works it might or might not get properly processed by the primary server afterwards.